Contact us

BOOK A PRESENTATION

The Summer Security Checklist Every Remote Worker Should Pack

NO NAME
By Ivan Vedak, Information Security Manager at ASEE

Summer means vacations, travel, and working from some pretty unconventional locations - cafés, airports, hotel rooms, beaches with a hotspot. Unfortunately, that same relaxed atmosphere is exactly what attackers are counting on. Distracted, tired, and slightly off their usual routine, even careful people cut corners they wouldn't cut at their desk. And that's precisely the window attackers are looking for.

Here's what deserves your attention when work travels with you.

Public Wi-Fi: proceed with caution

Free Wi-Fi at the airport or hotel is tempting, but these networks are frequently unsecured or poorly configured, and attackers can intercept traffic or set up a rogue access point with a name close enough to fool you at a glance. Easy as "Hotel_Guest_WiFi_Free" instead of "Hotel_GuestWiFi." Before connecting, confirm the exact network name with staff, and use a VPN for any work-related traffic without exception. No VPN available? Use mobile data or your own hotspot instead - a few extra megabytes cost less than a compromised account.

Devices and physical security

A laptop or phone left on a café table while you grab your coffee is all it takes for someone to walk off with it in seconds. And they will. Unattended devices in transit hubs are a known target of opportunity, not a hypothetical. Keep devices with you at all times, or lock them in the hotel safe, never in an unattended room without supervision, and never left visible inside a parked car. Lock your screen even when you step away for a moment, especially in shared spaces and busy work areas where a "moment" is all anyone needs.

Watch out for shoulder surfing

Working on sensitive documents on a plane or train means the person next to you can read your screen just as easily as you can. If you must work while in transit, use a privacy screen filter, and where possible avoid accessing sensitive systems (HR data, financials, contracts) until you're somewhere more private. It's a low-effort habit that closes a surprisingly common gap.

Charging devices: the "juice jacking" risk

Public USB charging stations at airports can be compromised to deliver malware through the data pins of the charging cable - the same cable that's supposed to just top up your battery. Bring your own charger with a wall outlet, or use a power bank. If a public USB port is genuinely your only option, use a USB data blocker adapter, which passes power through but blocks the data connection.

MFA: your safety net when things go wrong

Travel is exactly when credentials are most likely to be exposed. A shoulder-surfed password, a session hijacked over a spoofed hotspot, a phished login page that looked convincing enough at 6 a.m. before a flight. Multi-factor authentication doesn't prevent every mistake, but it's the layer that turns a stolen password into a dead end rather than a breach. Before you travel, confirm your MFA method actually works away from your usual setup, an authenticator app that depends on push notifications, for instance, needs a working data connection, so make sure you have a backup method (like a one-time code) that doesn't.

Travel phishing

Every summer brings a spike in fake emails about "an issue with your flight booking," "your accommodation has been cancelled," or "a gate change" - perfect opportunities for phishing. This is all classic bait acting as seasonal urgency. Check the sender address, don't click on suspicious links, and verify any booking directly on the official website rather than through a link in an email. If it's urgent enough to threaten cancelling your trip, it's urgent enough to verify through a second channel.

Before you finish packing, a short checklist

  • Update the operating system and security patches on all devices
  • Confirm disk encryption (BitLocker/FileVault) is turned on
  • Turn on your VPN before connecting to any public network
  • Back up important data before you leave
  • Save the IT support contact details in case a device is lost or stolen
  • Double-check that your MFA backup method works without relying on hotel or roaming data

If something happens

Report a lost or stolen work device, a suspected account compromise, or a phishing attempt during travel to your InfoSec team or IT support as soon as possible, even if you're not sure the incident is real. A false alarm costs a few minutes of someone's time; a delayed report can cost a lot more. A fast response, account lockout, remote wipe, is usually what separates a minor inconvenience from a serious security incident.

A few minutes of setup now means you actually get to disconnect later. Have a good trip.

Want to learn more about cybersecurity trends and industry news?

SUBSCRIBE TO OUR NEWSLETTER

CyberSecurityhub

chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram